Privacy Policy
Last updated: August 8, 2026
This Privacy Policy explains how SaaS100 Studio (“SaaS100,” “we,” “us”), operated from India, collects, uses, and shares information through SaaS100 Engage (the “Service”) — a customer engagement platform that lets a business (a “Workspace” or “Customer”) manage its own customers across channels like WhatsApp, Email, SMS, and connected social/business platforms. This Policy is framed to meet India's Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Information Technology Act, 2000 and its rules.
Under the DPDP Act, we act as a Data Processor for the contact and conversation data (“Personal Data”) a Workspace uploads or receives through the Service — the Workspace is the Data Fiduciary for that data and determines why and how it is processed. We act as the Data Fiduciary for account and billing information about the Workspace itself. If you are a customer of one of our Workspaces (e.g. you messaged a business that uses SaaS100 Engage), that business is the Data Fiduciary for your data — contact them directly, or see “Your rights” below for how we assist with those requests.
Information we collect
- Account data: name, email, password (hashed), and workspace details for anyone who signs up for or is invited to a Workspace.
- Customer & conversation data: the names, phone numbers, email addresses, message content, tags, and custom fields a Workspace stores about its own customers, and the messages exchanged over connected channels.
- Connected-channel data: when a Workspace connects WhatsApp Business, Google Business Profile, Facebook/Instagram, or a similar channel, we receive the data that platform's API provides — e.g. messages, comments, page posts, or insights — strictly to power the features the Workspace enabled.
- Usage & device data: log data, IP address, browser type, and product usage events, used for security, debugging, and improving the Service.
- Billing data: handled by our payment processor; we do not store full card numbers.
How we use information
- To provide, maintain, and secure the Service (message delivery, the shared inbox, CRM, journeys/automation, analytics).
- To power optional AI features (e.g. AI Copilot draft replies and summaries) — AI output is always presented as a draft for a human to review before it reaches a customer or affects billing; it is never sent automatically.
- To communicate with Workspace administrators about their account, security, and billing.
- To detect, prevent, and respond to fraud, abuse, and security incidents.
- To comply with legal obligations.
We do not sell personal information, and we do not use Workspace customer data to train third-party models beyond what is required to generate the specific AI output a Workspace requested.
Who we share information with
We share information only with the service providers (“sub-processors”) needed to run the Service, each bound by a data processing agreement:
- Google Cloud Platform — hosting, database, and infrastructure.
- Anthropic — powers optional AI Copilot features, when a Workspace uses them.
- Meta (WhatsApp Business Platform, Facebook, Instagram) and Google (Business Profile) — only for the channels a Workspace explicitly connects, and only to send/receive the messages, posts, or comments that channel involves.
- Our payment processor, for billing.
We do not share data with third parties for their own marketing purposes.
Data retention
We retain Workspace and customer data for as long as the Workspace's account is active, and for a limited period afterward to allow recovery from accidental deletion, after which it is permanently deleted, except where we are required to retain it longer by law.
Security
Customer data is isolated per Workspace at the database level (row-level security), access tokens are never stored in browser local storage, and connected-channel credentials are encrypted at rest. See our Terms of Service for the full allocation of security responsibilities.
Your rights
As a Data Principal under the DPDP Act (or under an equivalent law elsewhere), you may have the right to access, correct, update, or erase your personal data, and to have grievances addressed. Workspace administrators can exercise these rights directly inside the product for their own account and customer records. If you are an end customer of a Workspace and want your data removed, see our Data Deletion Instructions, or contact the Workspace directly — they are the Data Fiduciary responsible for that data. You may also reach our Grievance Officer below.
International transfers
Our infrastructure is hosted on Google Cloud Platform. Data may be processed in regions outside your own; where required, we rely on standard contractual clauses or an equivalent safeguard with our sub-processors.
Grievance Officer (India)
In accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023, the Grievance Officer for SaaS100 Studio is:
- Name: [Insert Grievance Officer's name]
- Designation: [Insert designation]
- Email: grievance@saas100.studio
- Address: [Insert your business address, India]
Complaints will be acknowledged within 24 hours and resolved within 15 days, as required under Indian law.
Children's privacy
The Service is intended for business use and is not directed at children. We do not knowingly collect personal information from children.
Changes to this policy
We will post any material changes to this page and update the “Last updated” date above.
Questions about this page? Contact privacy@saas100.studio.